
d_link_880_bug
Static analysis of D-Link router firmware revealing buffer overflow vulnerabilities in HTTP handling, including CVE-2017-14948, with disassembly and…

Static analysis of D-Link router firmware revealing buffer overflow vulnerabilities in HTTP handling, including CVE-2017-14948, with disassembly and…

Post-authentication command injection exploit for Wavlink AC1200 routers. Leverages improper input sanitization in adm.cgi to execute arbitrary shell…

Microsoft-Office-Word-MSHTML-Remote-Code-Execution-Exploit

Static analysis of the DarkSword iOS WebKit exploit chain — delivery, staging, and CVE breakdown (CVE-2025-31277, CVE-2025-43529)

Proof-of-concept exploit for CVE-2025-0851, a file traversal vulnerability in Deep Java Library's tar/zip model extraction utility, enabling…

Technical analysis and proof-of-concept exploit for a command injection vulnerability (CVE-2025-60854) in D-Link AX1500 routers, enabling…

Fixed Docker build for CVE-2023-20052 ClamAV XXE exploit. Resolves OpenSSL 3.0 compilation errors using Ubuntu 18.04 with OpenSSL 1.0 for…

Proof-of-concept exploit and custom payload generator for CVE-2018-5146, including crafted OGG POC file and HTML-based exploit with CRC32 calculation…

Proof-of-concept exploit for CVE-2020-12124 targeting Wavlink AC1200 router, demonstrating unauthenticated command injection and stack buffer…

Proof-of-concept exploit for CVE-2020-2950, demonstrating AMF deserialization to Java deserialization in Oracle Business Intelligence, with debug…

Technical analysis and proof-of-concept exploit for CVE-2023-46604 in Apache ActiveMQ, demonstrating remote code execution via deserialization…

Exploit for ImageMagick CVE-2022-44268, demonstrating arbitrary file read via crafted image. Includes PoC and analysis for security testing.

Exploit for CVE-2020-35717 targeting Electron applications, demonstrating a specific vulnerability and providing a proof-of-concept for security…

Proof-of-concept for CVE-2018-9950, an out-of-bounds read vulnerability in Foxit Reader/PhantomPDF leading to information disclosure and potential…

This experimetal fuzzer is meant to be used for API in-memory fuzzing.